SUSE Linux Micro is a modern operating system primarily targeted for edge computing. This document provides a high-level overview of its features, capabilities, and limitations.
1 About the release notes #
These Release Notes are identical across all architectures, and the most recent version is always available online at https://www.suse.com/releasenotes.
Entries are only listed once but they can be referenced in several places if they are important and belong to more than one section.
Release notes usually only list changes that happened between two subsequent releases. Certain important entries from the release notes of previous product versions are repeated. To make these entries easier to identify, they contain a note to that effect.
However, repeated entries are provided as a courtesy only. Therefore, if you are skipping one or more service packs, check the release notes of the skipped service packs as well. If you are only reading the release notes of the current release, you could miss important changes.
1.1 Documentation and other information #
For the most up-to-date version of the documentation for SUSE Linux Micro, see:
Find change logs for public cloud images at the Public Cloud Information Tracker (PINT) at https://pint.suse.com/.
2 SUSE Linux Micro Version 6.0 #
These release notes apply to SUSE Linux Micro 6.0.
2.1 Installation #
2.1.1 Installation media #
Image based deployment images
Base OS Image (Base OS + podman only)
Plus QCOW version of this image (x86_64, aarch64. S390x)
Plus VMware (VMDK) version of this image (x86_64)
OS image (Base OS, salt-minion, KVM + libvirt packages)
Plus QCOW version of this image (x86_64, aarch64. S390x)
Plus VMware (VMDK) version of this image (x86_64)
OS image with RT kernel (x86_64 only), no KVM support on this image
Base OEM image – self-installation image (Base OS + podman only) for x86_64
OEM image – self-installation image (Base OS, salt-minion, KVM + libvirt packages) for x86_64
OEM image with RT kernel – self-installation image, no KVM support on this image for x86_64
Images other than QCOW or VMDK target bare metal deployments.
2.1.2 Additional container images #
SUSE Toolbox container for debugging, based on current SLE 15 SP, provided via registry.suse.com
PCP container image (unmodified)
2.1.3 High-level requirements #
Use of SUSE Linux Micro without a container runtime is only supported when SUSE Linux Micro is used as a KVM host and workloads are installed into KVM virtual machines. Running workloads directly on the OS is not supported, with the exception of system management software.
2.1.4 Installation modes #
SUSE Linux Micro 6.0 only supports deployment via images. An installer based installation method is not offered.
Customization of the installation process with the provided images can be done with Ignition and Combustion (pre-configured images and self-installing images).
We will offer select images with support for cloud-init with a later milestone.
2.1.5 Supported architectures #
Intel/AMD 64bit (
x86_64)Arm 64bit (
aarch64)IBM Z (
s390x)
2.1.5.1 Minimum hardware requirements #
SUSE Linux Micro 6.0 requires hardware to meet requirements on these architectures:
For AMD64 and Intel* 64 systems: Microarchitecture level x86-64-v2 or higher.
For IBM* Power LE systems: POWER10 or higher (see note below).
For Arm64* systems: Armv8.0-A or higher.
For IBM* Z systems: z14 or higher.
While SL Micro 6.0 can run on POWER9, this configuration is not supported.
2.1.6 Upgrade path #
An online migration of existing SUSE Linux Micro 5.5 installations to SUSE Linux Micro 6.0 is possible and is fully supported.
Upgrading from SUSE Linux Micro 5.5 is only possible via the transactional-update tool.
For the upgrade procedure, refer to https://documentation.suse.com/sle-micro/6.0/html/Micro-upgrade/index.html
2.1.7 Change in installation methods #
With previous releases we supported manual installation via a YaST based image. With SL Micro we have dropped support for this installation method and only focus on RAW image based deployments. The SelfInstall image variant has been extended to allow setting of various parameters to direct it and also enable an unattended installation using the SelfInstall image.
2.1.8 Installing SUSE Linux Enterprise Micro #
2.1.8.1 Unattended installation with Yomi (technology preview) #
To learn how to install a system with Yomi, see the SUSE Manager documentation, section Install using Yomi. Installation with Yomi is a technology preview.
2.1.8.2 Deploying pre-built images #
SL Micro is provided as raw images which can be deployed directly to a storage device, for example, a memory card, a USB stick, or a hard drive. SL Micro is also provided as images for specific hardware device with a customized software selection.
For a procedure of deploying an image refer to https://documentation.suse.com/sle-micro/6.0/html/Micro-deployment-raw-images/index.html
2.2 Changes affecting all architectures #
Information in this section applies to all architectures supported by SL Micro 6.0.
2.2.1 SHA1 to be disabled or mark unapproved #
Due to FIPS 140-3 certification requirements, the SHA1 cryptographic algorithm will be disabled or marked unapproved when running in FIPS mode.
2.2.2 SLE BCI for kernel modules (Driver Toolkit) #
A new Base Container Image (BCI) is now available to build and run kernel modules on SUSE Linux Micro, comparable to the upstream driver-toolkit.
The container includes the necessary kernel headers for both default and RT kernels on x86_64 and aarch64 architectures, providing a simple way to prototype and test drivers without giving access to SLE kernel binaries.
2.2.3 32-bit execution support disabled by default on x86-64 and AArch64 #
On the x86-64 and Arm 64-bit (AArch64) architectures, support for running 32-bit (AArch32 and ia32) applications has been disabled by default to reduce the system’s security attack surface.
To re-enable 32-bit execution on the x86-64 architecture, boot the system with the ia32_emulation=1 kernel parameter.
To re-enable 32-bit execution on the AArch64 architecture (provided the hardware physically supports AArch32), ensure that the arm64.no32bit_el0 kernel parameter is not set.
Other architectures are not affected by this change.
2.2.4 Full-disk encryption #
SL Micro is focused on distributed infrastructures/Edge deployments, which means systems running SL Micro are not necessarily within DCs or secure locations. We therefore have improved our security story and added support for full disk encryption (FDE) to SLE Micro.
2.2.5 Confidential compute #
We are offering capabilities for confidential compute on SL Micro via the included virtualization stack.
2.2.6 1:1 web-based system management #
Since SUSE Linux Micro is positioned to be used within decentralized infrastructures including Edge use cases and Industrial Edge, a system management based on current YaST2 is not within scope. Specifically, for Industrial Edge, a basic web-based system management was required. We have chosen the cockpit project as a base for that. Therefore, the cockpit packages are added to the common code base and adjusted for the Immutable OS setup of SUSE Linux Micro.
2.2.7 Real-time kernel #
For the Intel/AMD 64bit architecture (x86_64) the real-time (rt) kernel is provided in addition to the default kernel. Support for RT includes support for Kernel Live Patching on the RT kernel. Note: When using the RT kernel, KVM is not supported, and workloads need to be run within containers Containers need special treatment with RT.
2.2.8 Security/security framework #
With SLE we fully support AppArmor and in addition provide the framework for SELinux – without providing and supporting a policy for SELinux. On SUSE Linux Micro we do not support AppArmor. SUSE Linux Micro only supports SELinux and in addition we ship a supported policy. On top of that, we will look into providing dedicated SELinux policies for the containers we already provide or support on top of SUSE Linux Micro (PCP and Nvidia). SUSE Linux Micro 6.0 will have SELinux in enforced mode as a default.